Forumshttps://software.intel.com/en-us/view/forum-page-default/36981
envPro Expert Center Linkhttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/741991
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>There is an additional forum that assists with Intel AMT questions: <a href="https://communities.intel.com/community/tech/vproexpert">Intel vPro Expert Center</a></p>
</div></div></div>Fri, 18 Aug 2017 17:01:40 +0000Joseph O. (Intel)741991 at https://software.intel.com Intel SA 00075 Security Advisory for Active Management Technologyhttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/733638
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>There has been a lot of talk about security concerns in regards to AMT, here is a synopsis to the situation</p>
<ul>
<li>We have received a report of a vulnerability in certain versions of Intel’s manageability firmware.</li>
<li>This vulnerability does not exist on consumer PCs.</li>
<li>This issue only affects business PCs using Intel® Active Management Technology (AMT), or Intel® Standard Manageability (ISM) or Intel® Small Business Technology (SBT). The vast majority of these is deployed at large companies.</li>
<li>We are not aware of any exploit for this vulnerability.</li>
<li>We are working with equipment manufacturers to make a firmware update available as soon as possible, and will share more details when we can.</li>
<li>Detection Guide and Tool is available to provide to customers and/or for CC agents to assist customers - <a href="https://downloadcenter.intel.com/download/26755">Intel-SA-00075 Detection Guide</a>.</li>
<li>The Detection Tool provides steps for single Windows GUI and Command Line Tool. (This guide and tool is for systems running Windows, specific guide for Linux-based systems is pending</li>
<li>A Mitigation Guide is available to provide to customers and/or for CC agents to assist customers - <a href="https://downloadcenter.intel.com/download/26754">Intel SA 00075 Mitigation Guide</a>. (This guide is for systems running Windows, specific guide for Linux-based systems is pending)</li>
<li>Full Security Advisory can be found at -<a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr"> Intel SA 00075 Security Advisory</a></li>
</ul>
<p><strong>Important links</strong></p>
<ul>
<li><a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr">Intel SA 00075 Security Advisory</a></li>
<li><a href="https://downloadcenter.intel.com/download/26754">Intel SA 00075 Mitigation Guide</a>.</li>
<li> <a href="https://downloadcenter.intel.com/download/26755">Intel-SA-00075 Detection Guide</a></li>
</ul>
<p> </p>
</div></div></div><section class="field field-name-field-zone field-type-taxonomy-term-reference field-label-above clearfix">
<h2 class="field-label">Zone:&nbsp;</h2>
<ul class="field-items">
<li class="field-item even">
<a href="/en-us/taxonomy/term/36708" typeof="skos:Concept" property="rdfs:label skos:prefLabel">Business Client</a> </li>
</ul>
</section>
Fri, 05 May 2017 18:25:12 +0000Joseph O. (Intel)733638 at https://software.intel.comNew Intel® AMT and HLAPI SDKs posted (v11.6)https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/563396
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Intel® AMT SDK <a href="https://software.intel.com/en-us/articles/download-the-latest-intel-amt-software-development-kit-sdk/">https://software.intel.com/en-us/articles/download-the-latest-intel-amt-software-development-kit-sdk/</a></p>
<p>Intel® AMT <strong>HLAPI </strong>: <a href="https://software.intel.com/en-us/articles/intel-amt-high-level-api-intel-manageability-library-to-manageability-webpage">https://software.intel.com/en-us/articles/intel-amt-high-level-api-intel-manageability-library-to-manageability-webpage</a></p>
</div></div></div>Fri, 24 Jul 2015 14:57:49 +0000Colleen C. (Intel)563396 at https://software.intel.comAuto Login after connect to Server.https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/755260
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Hi Team,</p>
<p>We have implement Mesh Central server and authenticate user from AD to connect our server. We have requirement to auto login to server after connect. </p>
<p>Earlier we are using :</p>
<p>echo "Connecting to 192.168.104.69"<br />
$Server="192.168.104.69"<br />
$User="Administrator"<br />
$Password="1234"<br />
cmdkey /generic:TERMSRV/$Server /user:$User /pass:$Password</p>
<p>for auto login. But we want to auto login through Mesh Central. We block the rdp port on our server.</p>
<p>Any help will be highly appreciated. </p>
<p>Regards</p>
<p>Deepak </p>
</div></div></div>Wed, 31 Jan 2018 14:55:11 +0000Deepak S.755260 at https://software.intel.comvPro issues with X1 Tablet 2nd Genhttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/755171
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Hi,</p>
<p>Just got an X1 Tablet 2nd Gen (model 20JC) and am working on setting up vPro. No wired NIC so I'm finding this article useful:</p>
<p><a href="https://software.intel.com/en-us/articles/an-introduction-to-intel-active-management-technology-wireless-connections">https://software.intel.com/en-us/articles/an-introduction-to-intel-active-management-technology-wireless-connections</a></p>
<p>The machine is primarily a desktop replacement and is connected to a Lenovo USB-C dock for power, Ethernet, and two external monitors. One of the monitors goes off the dock's native DisplayPort; the other external monitor goes through USB to an old Pluggable dock. AMT firmware and software are current--from MEWinINfo.exe:</p>
<p>BIOS Version N1OET37W (1.22 )<br />
MEBx Version 11.0.0.0010<br />
GbE Version Unknown<br />
Vendor ID 8086<br />
PCH Version 21<br />
FW Version 11.8.50.3425 LP<br />
Security Version (SVN) 3<br />
LMS Version 11.7.0.1043<br />
MEI Driver Version 11.7.0.1040<br />
Wireless Hardware Version 2.1.77<br />
Wireless Driver Version 20.10.2.2</p>
<p> </p>
<p>I got Wi-Fi enabled for vPro using the WebUI (took me a while to figure out I had to do that from the host system, e.g. <a href="http://localhost:16992/">http://localhost:16992/</a>). After that, I was able to connect from another machine on the LAN. Then, using Mesh Commander 0.5.8, I set up a certificate for the machine and enabled TLS. So far so good!</p>
<p>I have three issues:</p>
<p>1. Per the article linked above, AMT should work in S5 (power off). I can shut down remotely from Mesh, but once down, the machine is not on Wi-Fi. I confirmed in my router that it was offline.</p>
<p>2. If a user is logged in and I try to start a remote KVM session from Mesh, I just see some strange icons in Mesh (<a href="https://www.mcbsys.com/downloads/vProKVM.png" rel="nofollow">screenshot</a> below) and the user does not get the dancing border. However, if the screen is locked (from a Windows perspective), Mesh can connect, the user sees the border, and I can log on remotely and work as normal in Mesh KVM. The second external monitor, connected through the USB hub, doesn't work, but that's not a big deal. What is a kinda big deal is that the KVM can't connect to an active session; here's what it looks like when I try that:</p>
<p><img src="https://www.mcbsys.com/downloads/vProKVM.png" /> </p>
<p>3. When the system boots, it is connected to the dock and thus to the wired LAN. (The dock has a non-vPro Realtek NIC.) It seems that in this state, even though Wi-Fi is set to connect automatically, Windows 10 does not turn on Wi-Fi. This means vPro is not available unless the user manually connects to Wi-Fi.</p>
<p>Thanks for your help,</p>
<p>Mark Berry<br />
MCB Systems</p>
</div></div></div>Sun, 28 Jan 2018 02:45:32 +0000mcbsys755171 at https://software.intel.comSecurity BIOS updates pulled out for NUC's. Why?!https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/754838
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Dear Intel,</p>
<p>Any word why the most recent security BIOS updates were pulled and are no longer available? I've checked NUC5i5RYH and NUC7i5DNHE and for both these are gone. I am bit concerned as I've already updated to the version which was revoked. Should I be concerned?</p>
<p>Chris</p>
</div></div></div>Tue, 23 Jan 2018 07:41:32 +0000Chris B.754838 at https://software.intel.comUsing linux iTCO_wdt driver on i3-7100https://software.intel.com/en-us/forums/intel-business-client-software-development/topic/754812
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Hi,</p>
<p>I’m trying to get the TCO watchdog to work on i3-7100 on ASUS Desktop PC VivoMini VC66-B018Z (<a href="https://www.asus.com/us/Mini-PCs/VivoMini-VC66/">https://www.asus.com/us/Mini-PCs/VivoMini-VC66/</a>). </p>
<p>I have attached the output of dmidecode to this email.</p>
<p>I’m using a homebrew linux distribution with linux kernel 4.9.22 and I have been using the TCO driver with this software stack on other hardware platforms without any issues.</p>
<p>On the Asus VC66 when insert the TCO watchdog driver I get the following logs:</p>
<p>[15321.181802] iTCO_wdt: Intel TCO WatchDog Timer Driver v1.11<br />
[15321.181939] iTCO_wdt: Found a Intel PCH TCO device (Version=4, TCOBASE=0x0400)<br />
[15321.182061] iTCO_wdt: initialized. heartbeat=30 sec (nowayout=0)</p>
<p>But then when I program a timeout and stop pinging the watchdog the unit does not reboot. Nothing happens, the unit continues to operates normally.</p>
<p>I have investigated and found out that the TCO_RLD register does not decrement. </p>
<p>When I cat /sys/class/watchdog/watchdog0/timeleft I always get the same value (the value that I programmed in timeout)</p>
<p>I have added a couple of prints in the driver to display the important TCO related registers in the set timeout function. Here are the values:</p>
<p>[ 7732.805330] iTCO_wdt: SMI_EN = 0x90002023<br />
[ 7732.805335] iTCO_wdt: GC = 0x0<br />
[ 7732.805338] iTCO_wdt: TCO_RLD = 0x32<br />
[ 7732.805342] iTCO_wdt: TCO1_STS = 0x0<br />
[ 7732.805346] iTCO_wdt: TCO2_STS = 0x0<br />
[ 7732.805349] iTCO_wdt: TCO1_CNT = 0x1000<br />
[ 7732.805353] iTCO_wdt: TCO2_CNT = 0x8<br />
[ 7732.805357] iTCO_wdt: TCOv2_TMR = 0x32</p>
<p>When I check these values against the TCO spec they look good to me. (i.e.: NR bit is cleared in GC register, TCO_EN is set in SMI_EN register, TCO_TMR_HALT is cleared in TCO1_CNT)</p>
<p>Am I missing something?</p>
<p>Is there anything else that I could check to find out why the TCO timer is not counting down?</p>
<p>Can anyone help me with this issue?</p>
<p>Is it the appropriate forum for this question?</p>
<p>BR,<br />
Pierre</p>
</div></div></div><div class="field field-name-field-attachments field-type-file field-label-hidden"><div class="field-items"><div class="field-item even"><table class="sticky-enabled">
<thead><tr><th>Attachment</th><th>Size</th> </tr></thead>
<tbody>
<tr class="odd"><td><span class="file"><a href="https://software.intel.com/sites/default/files/managed/e2/9c/dmidecode.txt" class="button-cta" type="text/plain; length=21403">Download</a><img class="file-icon" typeof="foaf:Image" src="https://software.intel.com/sites/all/themes/isn3/css/images/attachment_icon.png" alt="text/plain" title="text/plain" /> <a href="https://software.intel.com/sites/default/files/managed/e2/9c/dmidecode.txt" type="text/plain; length=21403">dmidecode.txt</a></span></td><td>20.9 KB</td> </tr>
</tbody>
</table>
</div></div></div>Mon, 22 Jan 2018 17:58:59 +0000Pierre A.754812 at https://software.intel.comUnable to remove Intel RCS Softwarehttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/754608
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Hi All,</p>
<p>Our Intel RCS install has become corrupt and I am trying to clean it up to do a re-install. The directory structure and db have been removed and the software is not visible in "Programs and Features"</p>
<p>However when I try to run the installer, it detects components as being installed still as I am presented with the "The installer has detected that at least one Intel SCS component is already installed on this computer". When I select "remove all components" I get the following error "Error 100. the parameter REMOVE must not be set".</p>
<p>If anyone could help finish the clean up so that I can do the re-install that would be great. I am assuming it is checking the existence of a registry key or something in wmi.</p>
<p>Thanks</p>
</div></div></div>Tue, 16 Jan 2018 00:01:16 +0000Clarke, Steve754608 at https://software.intel.comNUC7i5DNH - AMT System Defense and buggy, non removable filterhttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/754244
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>I am working with AMT on NUC7i5DNH using MeshCommander 0.5.7. Currently, exploring the system defense part and network filtering.</p>
<p>The current issue is that I have a filter which could not be removed (see attached screenshots). I can the filter to profile, and then it is visible in the profile. However even if the profile is deselected and removed, and seemingly there is nothing else refering to the filter it still could not be removed (the error is that there is some kind of reference to it still.</p>
<p>Can you help to see how this filter could be removed?? Unfortunately I cannot de-configure AMT as the system is remote and physically very far.</p>
<p>Thanks in advance.</p>
<p>Chris</p>
</div></div></div><div class="field field-name-field-attachments field-type-file field-label-hidden"><div class="field-items"><div class="field-item even"><table class="sticky-enabled">
<thead><tr><th>Attachment</th><th>Size</th> </tr></thead>
<tbody>
<tr class="odd"><td><span class="file"><a href="https://software.intel.com/sites/default/files/managed/93/a3/Filter1.png" class="button-cta" type="image/png; length=26509">Download</a><img class="file-icon" typeof="foaf:Image" src="https://software.intel.com/sites/all/themes/isn3/css/images/attachment_icon.png" alt="image/png" title="image/png" /> <a href="https://software.intel.com/sites/default/files/managed/93/a3/Filter1.png" type="image/png; length=26509">Filter1.png</a></span></td><td>25.89 KB</td> </tr>
<tr class="even"><td><span class="file"><a href="https://software.intel.com/sites/default/files/managed/9e/df/Filter2.png" class="button-cta" type="image/png; length=40726">Download</a><img class="file-icon" typeof="foaf:Image" src="https://software.intel.com/sites/all/themes/isn3/css/images/attachment_icon.png" alt="image/png" title="image/png" /> <a href="https://software.intel.com/sites/default/files/managed/9e/df/Filter2.png" type="image/png; length=40726">Filter2.png</a></span></td><td>39.77 KB</td> </tr>
<tr class="odd"><td><span class="file"><a href="https://software.intel.com/sites/default/files/managed/af/0a/Filter3.png" class="button-cta" type="image/png; length=37211">Download</a><img class="file-icon" typeof="foaf:Image" src="https://software.intel.com/sites/all/themes/isn3/css/images/attachment_icon.png" alt="image/png" title="image/png" /> <a href="https://software.intel.com/sites/default/files/managed/af/0a/Filter3.png" type="image/png; length=37211">Filter3.png</a></span></td><td>36.34 KB</td> </tr>
</tbody>
</table>
</div></div></div>Sun, 07 Jan 2018 21:41:56 +0000Chris B.754244 at https://software.intel.comMeshCommander 0.5.7 with latest NUC 7i5DNHE - wifi profiles problemhttps://software.intel.com/en-us/forums/intel-business-client-software-development/topic/752394
<div class="field field-name-body field-type-text-with-summary field-label-hidden"><div class="field-items"><div class="field-item even" property="content:encoded"><p>Hi!</p>
<p>I have just received the new NUC7i5DNHE, enabled AMT and started playing with MeshCommander. What I have quickly found is that on this platform it is not possible to add wireless profiles using MeshCommander (it fails silently), but it is possible to do so using default AMT web interface.</p>
<p>Since I have not found any other way of reporting the issue i am reporting it here.</p>
<p>Kind regards,</p>
<p>Chris</p>
</div></div></div>Fri, 08 Dec 2017 07:53:50 +0000Chris B.752394 at https://software.intel.com